Twitter said to be testing two-step security in wake of AP hack
crave.cnet.co.uk
crave.cnet.co.uk
Does anyone have any insight on why Twitter haven't implemented that sort of system (nominated accounts able to tweet from a corporate account) and seemingly abandoned the idea in 2010? One of our Twitter accounts has ~30,000 followers and we have to share the password amongst the company in a spreadsheet, that sort of poor security is encouraged by a single login model, with all the previous high profile account compromises it seems strange Twitter hasn't addressed this before. Maybe someone knows why, or can speculate why?
I'm not saying that it's acceptable that Twitter leaves that in the hands of vendors/users, I'm genuinely curious and wondering why the idea was parked in the first place.
I'd guess that it is part of a future offering from Twitter, but who knows.
I don't have any current insight into the status of Contributors, and won't speculate, but the feature has been stagnant for almost 3 years now (just like Lists).
Twitter really needs shared accounts + required two-factor for the personal accounts.
All computer users understand passwords (and the basics of password complexity/secrecy) at this point. That covers the "something you know" factor.
Many users conceptually understand a "something you have/are" factor in the form of biometric scans or smartcards. Unfortunately, those approaches are not practical to deploy outside a controlled enterprise setting.
On the Web, the only approach that isn't a non-starter today is TOTP, what Google Authenticator uses. Unfortunately, basically zero users understand this, creating a large education issue, and frankly it's a pain in the neck for users ("why do I need to go find my phone to log in??"). The upside is it's easy for Web app developers to integrate TOTP, and it adds significantly to account security if used correctly.
Facebook and Google have offered this as an option for quite some time, and with Twitter's current prominence as part of corporate advertising, I am surprised they are this late to the party.
His line of work has him dealing with some pretty sensitive material, and a two-factor authentication is required for it... something that, when introduced, was a source for many calls and angry shouting. I could have deferred this to their tech people, but I'd much rather spare them the anguish. ;)
Bottom line: It's getting better, but you are still, unfortunately for us all, way too optimistic.
In what way? Bloomberg uses custom hardware developed in-house (the "B-unit") for four-factor authentication (password, biometric, visual sync, token). These devices are sent to customers all over the world where there is no control over them. All of the device and biometric enrollment is done through the software remotely when the device is received by the end user. So in my experience it is definitely possible to do this outside of the typical employee/enterprise scenario.
Definitely an interesting device.
Kudos for being horribly late and reactive instead of proactive?
This should have been implemented long long ago imo. Though i do give them more slack than with all of our banking institutions that still don't offer two-factor. But these recent events show how importing two-factor(or security in general) for even things like social media are.
Bad news: Now you have to go the extra mile to make sure it isn't misused.
I think this still falls into the category of problems that it's good to have, barely.
Couldn't they even achieve this quickly using Twilio to send SMS token codes to users who opt to have 2 factor auth?
Maybe there isn't a single solution that meets the needs of every user.
Reporters in the field? Especially in a breaking news situation where they want to be first.
They have a news desk that is staffed 24hrs per day. Surely a person there could monitor tweets or communications from reporters in the field. I'd even expect there to be a different individual with the keys to the Twittermachine.